A Trezor data breach at its shipping provider has affected 67,000 additional customers in the United States, taking the total number of people exposed to 81,000.
The cryptocurrency hardware wallet company said the newly identified customers placed orders between November 2019 and August 2021. Their names, email addresses, telephone numbers, shipping addresses and order numbers were exposed.
Trezor initially disclosed the incident on 13 August, saying almost 14,000 customers had been affected. Those customers ordered between 10 May and 8 August 2026 and included people in the UK, Brazil, Colombia, Italy, Portugal and Sweden, as well as the US.
The data was held by ShipMonk, a third-party shipping and logistics provider. Trezor said ShipMonk had failed to remove the information from its systems, despite contractual requirements and repeated written assurances that the deletion had taken place.
“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data,” Trezor said. “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.”
The company said its own systems had not been compromised and that the breach had not affected its services or the security of Trezor devices.
Customers whose details were exposed have been warned to expect a heightened risk of phishing. Trezor said the information could be used in scam emails, fraudulent telephone calls or letters, and could potentially create physical security risks.
Metabase vulnerability linked to ShipMonk breach
The precise method used to access ShipMonk’s systems has not been publicly detailed by Trezor. However, breach notification emails sent to customers said attackers exploited a vulnerability in Metabase, a third-party analytics platform.
Metabase has previously said that attackers exploited a critical SQL injection zero-day flaw after obtaining administrator access to customer installations. The campaign involved the theft of data from compromised instances.
ShipMonk has also received extortion emails from the ShinyHunters cybercrime group, according to reports. Other companies linked to the wider Metabase campaign, including online forms platform Tally and laptop manufacturer Framework, have also notified customers about data breaches.
The incident is not Trezor’s first breach involving a third-party provider. In January 2024, attackers compromised its support ticketing portal and accessed information belonging to about 66,000 users. That data was later used in phishing attempts seeking victims’ 24-word wallet recovery phrases.
